CVE-2023-31698: Bludit

Medium severity, CVSS 5.4. EPSS: 2.6% chance of exploitation in the next 30 days.

Bludit v3.14.1 is vulnerable to Stored Cross Site Scripting (XSS) via SVG file on site logo. NOTE: the product's security model is that users are trusted by the administrator to insert arbitrary content (users cannot create their own accounts through self-registration).

Affected products

  • Bludit Bludit: version 3.14.1 only

Published 2023-05-17. Last modified 2026-06-17.